Number of App Installs (according to Google Play Store at time of analysis)

500,000,000+

Opt out of Ads Personalisation (Google Settings)

Not Enabled (Default Setting)

Observed Behaviour

This documentation demonstrates actions taken by the test user and the apps subsequent responses.

Test user action 1: The user taps on the application icon, which opens the applicationResponse from app: The application is initialised and the following data is sent and received by the app:

Immediately after the app is opened, the following data is sent to graph.facebook.com (Graph)

The following HTTP GET request is made to graph.facebook.com

GET https://graph.facebook.com/v3.0/1810807739198766?fields=supports_implicit_sdk_logging%2Cgdpv4_nux_content%2Cgdpv4_nux_enabled%2Cgdpv4_chrome_custom_tabs_enabled%2Candroid_dialog_configs%2Candroid_sdk_error_categories%2Capp_events_session_timeout%2Capp_events_feature_bitmask%2Cseamless_login%2Csmart_login_bookmark_icon_url%2Csmart_login_menu_icon_url&format=json&sdk=android HTTP/1.1

“Thank you for taking the time to review our privacy practices. We take the privacy of our users very seriously, so we’re glad to have the chance to cooperate with Privacy International.

To demonstrate our commitment to the privacy of our users, we’ve undergone the robust certification process for compliance with the GDPR and we’re also members of the ePrivacyApp certification program (the “Program”). ePrivacy is an independent, third-party organization specializing in digital data protection. As part of the Program, Outfit7's Talking Tom and Friends and other characters applications are subject to a comprehensive inspection and certification of the applications with respect to ensure that the applications live up to the high demands in the field of data protection and can provide a high level of security of end user data.

Please note that we are aware of the problem with Facebook SDK and we have been actively working on finding solutions to ensure privacy of our end user data. Please see exhibit A - Jira Ticket - which clearly shows that we started working on updating Facebook SDK already in September, 2018 in order to ensure that end user data is being collected in compliance with the law. For the EEA territory, which includes UK, the internal instructions were, that all app events, together with the advertising ID, sent to graph.facebook.com must be disabled for users that are below 16 or do not pass the localized age gate (meaning age gate, which is set in accordance with the local legislation regarding the year of consent). For users that are above 16 or pass the localized age gate, Facebook login SDK must be added to our consent tool and no app event data (including advertising ID), should be sent to graph.facebook.com unless user gives consent. On October 17, 2018, we have decided to entirely disable transmission of app events data (including advertising ID) to graph.facebook.com regardless of the fact whether user passed the age gate or not. Please note that in order for us to update Facebook SDK in a particular app, the app needs to be updated, which was done in a regular course of updates. The first app that was updated with the updated Facebook SDK was Talking Tom Gold Run (November 20, 2018). My Talking Tom and My Talking Angela apps were updated on December 20, 2018. All the other apps, including My Talking Hank, will get updated by the end of February 2019.”